Penalties: three tiers and a calculator mindset

Lesson 4 of 6 in Governance, Enforcement, Penalties, and Sandboxes.

Article 99 builds a three-tier fine structure, and the design principle is familiar from the GDPR: caps expressed as a fixed sum or a percentage of total worldwide annual turnover, whichever is higher — so no company is too big for the fine to hurt. Member States set the actual penalty rules and their authorities impose them (notifying the Commission of their regimes); the Act fixes the ceilings and the aggravating/mitigating factors: nature, gravity and duration; intent or negligence; corrective actions taken; prior fines; size and market share; financial benefit gained or losses avoided; degree of cooperation.

One deliberate inversion protects small players: for SMEs and startups, each fine is capped at the lower of the percentage or the fixed amount — the exact opposite of the whichever-is-higher rule that applies to everyone else.

The penalty architecture (Arts 99–101)
TierCeilingWhat triggers itNotes

Tier 1 — prohibited practices

€35M or 7% of worldwide annual turnover, whichever is higher

Non-compliance with the Article 5 prohibitions — social scoring, untargeted face scraping, and the rest

The highest percentage cap in EU digital law short of the DMA’s 10% — above GDPR’s 4%

Tier 2 — operator and notified-body obligations

€15M or 3%, whichever is higher

Breach of most substantive duties: provider obligations (Art 16), authorised representatives (22), importers (23), distributors (24), deployers (26), notified bodies (Arts 31, 33(1), (3), (4), 34), and Art 50 transparency duties

The everyday tier — where Annex IV gaps, missing oversight, and skipped registrations land

Tier 3 — misleading information

€7.5M or 1%, whichever is higher

Supplying incorrect, incomplete, or misleading information to notified bodies or competent authorities

Lying about compliance is fined separately from failing to comply

SMEs and startups

Each ceiling applies at the lower of the amount or percentage

All of the above tiers

The inverted rule — proportionality for small operators (Art 99(6))

Union institutions (Art 100)

Up to €1.5M (prohibited practices) / €750k (other obligations)

AI Act breaches by EU institutions, bodies, and agencies

Imposed by the EDPS — the Union polices itself on a smaller scale

GPAI providers (Art 101)

Up to €15M or 3%, whichever is higher

Intentional or negligent infringement of GPAI obligations, or failure to comply with document requests, evaluations, or access demands

Imposed by the Commission — the only fines in the Act levied centrally

Interactive sorting exercise: Fine calculator triage: drop each violation into the penalty lane it belongs to.

Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.